toxic-bert text toxicity classifier (6 labels)

models.skillsafe.ai/toxic-bert-q8@65cbc260/

Vetted New WebGPU

Text classification model for transformers.js (q8). Runs on WASM or WebGPU — 106 MB downloaded once from models.skillsafe.ai, then cached for every SkillSafe app that uses it. Inference happens on your device; nothing you enter is uploaded to load it, and it never costs a credit. Weights from Hugging Face · skillsafe-ai/toxic-bert, pinned at 881c89217e0c — also loadable straight from Hugging Face outside SkillSafe (how).

Share

Details

Catalogue idtoxic-bert-q8@65cbc260
Runtimetransformers.js ≥ 3.0.0
DeviceWASM, WebGPU
Variantq8
Download106 MB · 1 file
LicenceApache-2.0 · notice
Pinned at881c89217e0c5871cf67ffe8ef08453ea016a0ba
ApprovedSep 22, 2026
Statusactive — every file is a live vetted hash

Files

Each file is served at an immutable URL; the canonical form is the SHA-256 itself. Tokenizer and config JSON are not here by design — they ship in your app bundle.

PathFormatSizeSHA-256
onnx/model_quantized.onnx onnx 106 MB 620012c9bed1…ac3f73

Signature

Graph inputs and outputs read from the ONNX bytes at vetting — the tensor names your session.run() call feeds and reads. Symbolic dimensions are shown by name.

Inputs

  • input_ids int64 [batch_size, sequence_length]
  • attention_mask int64 [batch_size, sequence_length]
  • token_type_ids int64 [batch_size, sequence_length]

Outputs

  • logits float32 [batch_size, 6]
Use it in an app declaration · SDK loader · transformers.js · URLs · Hugging Face — generated from this entry

Add to the body of POST /v1/apps/{slug}/releases (or a release session). An unknown or withdrawn model is refused with a 400 naming it; the app page then shows "downloads 106 MB · runs on your device" and /models.txt carries the attribution.

{
  "models": [
    {
      "id": "toxic-bert-q8",
      "revision": "65cbc260"
    }
  ]
}

Evaluation

onnx.checker + onnxruntime CPU smoke run with zero-filled inputs at the declared shapes; per-file SHA-256 pinned to the source; ONNX output vs the PyTorch model from the same commit on real text (import.parity) — imported as published upstream, then checked. Evaluated Sep 22, 2026.

Parity against transformers BertForSequenceClassification from unitary/toxic-bert@4d6c22e74ba2, fp32 · logits

fileprecisionmax absmean abscosine / PSNR
onnx/model.onnxfp328.6e-62.9e-61.000000
onnx/model_quantized.onnxquantised0.1340.0290.999892

Runs under onnxruntime

Zero-filled inputs at the declared shapes, CPU execution provider on the converter host; the check is that the graph loads, runs, and emits the declared output shapes.

  • onnx/model.onnx: input_ids[1,8], attention_mask[1,8], token_type_ids[1,8] → logits[1,6] 4.4 ms
  • onnx/model_quantized.onnx: input_ids[1,8], attention_mask[1,8], token_type_ids[1,8] → logits[1,6] 3.1 ms

Toolchain: python 3.12.13 · platform Darwin 25.6.0 arm64 · torch 2.10.0 · onnx 1.23.0 · onnxruntime 1.30.0. Recipe models/recipes/toxic-bert.yaml (733756f7d1c1). Full manifest.json

Licence & attribution

Apache-2.0 · licence text · notice

toxic-bert: Unitary (Detoxify), Apache License 2.0. https://github.com/unitaryai/detoxify — ONNX export by Xenova (https://huggingface.co/Xenova/toxic-bert).

Apps that declare this model get this text in their generated /models.txt, so a licence that requires a notice always carries one.

Every file here was approved by exact SHA-256 after a structural audit of the graph, fetched from a content-pinned source, and is served credential-free at an immutable URL. The SDK re-verifies the hash on your device before it caches or returns anything. Missing a variant? Request it — or read how the registry works.